From one piece Be alert: targeted attacks on prominent Rustaceans 2 beliefs · simonwillison.net
-
Their words
Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.
-
korrents.com
Dependency cooldowns are currently the best defense against supply chain attacks via compromised package publishers.Their words
I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.